Blockchain investigator ZachXBT reported infiltrating a Chinese cryptocurrency-laundering syndicate allegedly linked to North Korea’s Lazarus Group, exposing a wallet cluster containing more than $12 million in proceeds from the $1.5 billion Bybit theft. Posing as a customer, he funded transactions with 349,700 USDC and accepted a 5% loss per order to obtain private communications and transaction details. He correlated broker-provided wallets, gas funding, advance transaction disclosures and a THORChain transaction with public blockchain records to trace stolen assets across multiple networks. The FBI previously attributed the February 2025 Bybit theft to North Korea under the activity name TraderTraitor.
Tether subsequently froze approximately 442,000 USDT associated with the identified cluster; The Defiant independently confirmed the address’s blacklisted status onchain. ZachXBT said he immediately shared findings with private-sector investigators and law enforcement but delayed publication for roughly 18 months because of investigative sensitivities. His claims that the syndicate laundered more than $1 billion, processed most of the stolen Bybit assets and operated from Hong Kong and mainland China remain unconfirmed. The freeze restricts movement of the affected tokens but does not establish that funds have been returned to victims.

Track how attackers are adapting to this technology.
16 events from the most recent confirmed update back to the earliest known activity.
ZachXBT published his investigation in a 12-post thread on X, assessing that the Chinese network had laundered more than $1 billion across multiple exploits for North Korea's Lazarus Group. The total and the broker's claims about processing most Bybit proceeds were not independently confirmed.
ZachXBT reported that Chinese actors moving proceeds from the reported $387.5 million Bitget exploit were also opening support tickets in public channels. Chainalysis linked that exploit to North Korea.
ZachXBT said Jimmy Green's Telegram account was deleted earlier in 2026. Someone else subsequently claimed the username.
The U.S. Treasury Department cut Huione Group, the operator of Huione Guarantee, off from the U.S. financial system.
Jimmy Green sent a screenshot showing funds being bridged, which ZachXBT matched by amount and timing to a THORChain order created minutes later.
ZachXBT funded a fresh Ethereum wallet with 349,700 USDC and began exchanging USDC for USDT on Tron through the broker. He accepted losses of approximately 5% per order to build trust and maintain access.
The FBI attributed the theft to North Korea and identified the activity as TraderTraitor. Its advisory warned that stolen assets were spreading across thousands of addresses on multiple blockchains.
Hackers stole approximately $1.5 billion in cryptocurrency from Bybit.
ZachXBT identified a 2024 freeze of 332,000 USDC linked to the Poloniex exploit that corresponded to broker Jimmy Green's account of approximately $300,000 being frozen from his team's funds.
The Defiant confirmed onchain that Tether's USDT contract marked the identified address as blacklisted and that it held 442,399 USDT. The address was a Uniswap V2 pool, consistent with ZachXBT's description of laundering through liquidity pools for illiquid tokens.
ZachXBT said Tether subsequently froze approximately 442,000 USDT associated with the Bybit-linked wallet cluster. The freeze did not establish that the assets had been returned to victims.
ZachXBT said he immediately provided his findings to private-sector investigators and law enforcement assigned to the Bybit case to support additional asset freezes. He withheld public disclosure for roughly 18 months because of investigative sensitivities.
Jimmy Green mentioned laundering $3 million in fraud proceeds for another client. ZachXBT traced those proceeds to a hot wallet associated with Huione Guarantee.
Three Solana addresses supplied by Jimmy Green helped ZachXBT identify a wallet cluster involving more than $12 million in Bybit proceeds. He reported tracking the funds across Bitcoin, Ethereum, Solana and Tron.
ZachXBT traced transaction-fee funding for Jimmy Green's receiving wallet to a wallet linked to Bybit exploit proceeds. The funding wallet also appeared on Bybit's public blacklist.
Following the Bybit theft, ZachXBT identified more than 15 accounts seeking assistance with transactions involving stolen funds in public Telegram and Discord groups. He approached a broker using the alias Jimmy Green and posed as a client to gain access to the alleged laundering network.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcethedefiant.io
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.